Feeds

Spammers unleash DIY phone number slurping web tool

Well it is Valentine's Day... How else are you going to get those digits?

5 things you didn’t know about cloud backup

Mobile spammers have released a DIY phone number harvesting tool, but instead of advertising it solely on criminals-only online hangouts, they're trying to flog it out in the open.

The availability of the utility turns the simple act of submitting a mobile number to a website something that might lead to the receipt of more SMS (text message) spam.

A new version of the phone number harvesting tool crawls the web and indexes mobile numbers, phone ID numbers, the names of the owner, and the associated mobile operator - among other information. Users of the tool can choose which country they want to target.

The harvested information is later used for various malicious and fraudulent purposes.

Key features of the tool include automatic recognition of Russian and Ukrainian mobile phone providers (based on its initial target market), indexing based on a region and city for both Russia and Ukraine, multi-threaded software allowing up to 100 “indexing streams”, as well as an option to collect only numbers attached to a particular mobile provider.

"Cybercriminals and spammers are not strangers to the concept of market segmentation," explained Dancho Danchev, a security researcher at Webroot, in a blog post.

"Just like true marketers, the developer of the tool has included the option to choose a specific region within the available countries, with the idea to assist in the inevitable malicious and fraudulent activity that will result from this phone number harvesting activity."

Danchev advises surfers to double-check whether any website that requests your phone number is actually listing it on the web. The phone number harvesting tool has yet to crawl through sites that require authorisation or spread outside Russia and the Ukraine, he said, but future versions are likely to expanding indexing capabilities and geographical reach, Danchev warned.

The DIY phone number harvesting tool is an example of a wider trend of selling tools that once were exclusively available to sophisticated cybercriminals to less elite cybercrooks though underground forums. Services that offers a means to launch managed SMS flooding and phone ring flooding have recently become available through these forums. Both managed SMS flooding and phone ring flooding are pitched as a means to “take care of your competitor’s phone lines” or a DDoS attack on phones instead of websites. However, these services might easily lend themselves to helping along more ambitious scams, such as flooding out a bank's call centres to prevent early reports of card fraud cash-out operations, according to Webroot.

"By starting to advertise these very same malicious (DIY) tools and services on publicly accessible forums, they’re proving that they’re willing to sacrifice a certain degree of OPSEC (Operational Security) for the sake of growing their business model and attracting new customers," Danchev reports. ®

The essential guide to IT transformation

More from The Register

next story
One HUNDRED FAMOUS LADIES exposed NUDE online
Celebrity women victimised as Apple iCloud accounts reportedly popped
Rubbish WPS config sees WiFi router keys popped in seconds
Another day, another way in to your home router
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NZ Justice Minister scalped as hacker leaks emails
Grab your popcorn: Subterfuge and slur disrupts election run up
HP: NORKS' cyber spying efforts actually a credible cyberthreat
'Sophisticated' spies, DIY tech and a TROLL ARMY – report
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?